URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gons28cl.top
Domain registrar:NICENIC -
Domain registration date:2023-11-24 06:16:19 UTC
Abuse complaint sent to registrar: Yes (2023-11-24 12:21:03 UTC to support{at}nicenic[dot]net)
Domain registry:TOP registry -
Abuse complaint sent to registry: Yes (2023-11-24 12:21:04 UTC to abuse{at}nic[dot]top)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-11-24 12:19:05 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :8

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-11-24 12:20:10 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ano
2023-11-24 12:20:10 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2023-11-24 13:07:30 188.114.96.9Not listedAS13335 CLOUDFLARENETn/ano
2023-11-24 13:07:30 188.114.97.9Not listedAS13335 CLOUDFLARENETn/ano
2023-11-27 13:13:47 188.114.96.0SBL686925AS13335 CLOUDFLARENETn/ano
2023-11-27 13:13:47 188.114.97.0Not listedAS13335 CLOUDFLARENETn/ano
2023-11-26 17:20:52 188.114.96.7Not listedAS13335 CLOUDFLARENETn/ano
2023-11-26 17:20:52 188.114.97.7Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-11-24 18:27:04http://gons28cl.top/build.exeOfflinedropped-by-PrivateLoader andretavare5
2023-11-24 12:20:10https://gons28cl.top/build.exeOfflinedropped-by-PrivateLoader Vidar ext andretavare5

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-12-01 11:19:37c2c5d319bc5fe424a8ea42a8626dd6b93b27f1a23aa45611df09ecf55dfa1dfaexeVidar
2023-12-01 03:42:41cc58fda6767d3d05772223f4267075b2dc2a63bc802a6026f3dbc1403e3efa17exeVidar
2023-11-30 11:36:5333b04a8d7bc2da4d5e00ce9acd0e5755daf961f1a8574ef84ba3d58761127d6aexeVidar
2023-11-30 04:04:57199c44e7bc7c65d6be9959d2d5875e9755104275de462698cd4f6ad94e57d25eexeVidar
2023-11-29 16:51:41b9a735c63c27f166faee59d63f03f01eadbd86b931de04a0d5ee2ceb148b1f68exe  
2023-11-29 10:24:158c5858fdc6044de48a8f22b1ae51eb6bfa45befe91c3a854b2b0a99b79d41581exeVidar
2023-11-29 06:19:2259d814713c61b046ff14a21e0ed83013b32d89eb7921bf0fb290379a331bfab6exe  
2023-11-28 16:43:12465bec204932baa110e7344f725d7a9acd5c1a599927e6a3a080aa31dc18101fexeVidar
2023-11-28 15:05:054e173bdad03b757e76bb6fdcec1c7d76240a517b1a3c8bd361eda3973f20a8bbexe  
2023-11-28 12:26:0380cdd2032cb437e285994a55b0e8ab9fff08cb9c79de90366292852f7b01eeb2exe  
2023-11-28 09:24:508a59a0e9b326966e4fb7353078bf82b765df754e575a3bfe3bb44220ffb41116exeVidar
2023-11-28 09:24:488a59a0e9b326966e4fb7353078bf82b765df754e575a3bfe3bb44220ffb41116exeVidar
2023-11-28 05:51:511b23847db328a1eb04e93c74451d481cbbaa4d7110fe87440b203a9dad36199aexeVidar
2023-11-27 17:11:3813934f7ce652204036c52c73deddeb2185b6d9be2ce5ca0622db4e46cbeba1caexe  
2023-11-27 11:14:32ec90def0c0badb54840cbf1fade3a70359ab5c85619a8f47105e8f19a1fc85e1exeVidar
2023-11-27 07:51:14adf857652ec7380cca32df7b9d0ecdcc4ed1dc9a9abf8a20c4417af037a24f46exeVidar
2023-11-27 05:42:13f13579b0dc3a0f742251c64fb5aab5e537fc8a82db32ac60775843d73e5b65fdexeVidar
2023-11-26 15:56:4523f0dc130aa22ad54a6935965d52a146a239ca9b7f4eca531cd74d3bdcde210eexeVidar
2023-11-26 13:19:318e70da316bb9865e7edda277430df66cdf6da7b34a0e8607ca28192164c7b6a8exeVidar
2023-11-26 03:54:387622fc8bbc24b2a897785d26cf343d51e1e89faf35783b658ff7b075d4686a81exeVidar
2023-11-25 14:21:5233da86a999f82f99598ab1a10ba98010501249231229051d78d35b826526e99aexeVidar
2023-11-25 10:47:37760cca934f2fb907c9a7b99dbf5affea9c01e8257b41d67a5ebc4968eebb982fexeVidar
2023-11-25 06:32:59e4593c2762d76c2532db610793c5480f2c40a4fd5097f4d7d5e1ccf4c8b6ada7exeVidar
2023-11-24 18:04:16d363eb55ceaf45f4732d7626ecf984aa9a84893e17201397fed96d803f57412fexeVidar
2023-11-24 15:47:36f8387edcff6a84de4faca34b7514533d4590711e3a06356d8b9ec1f4d94f172cexeVidar
2023-11-24 12:20:10096f1efe5d48906704852cbf6952abde0b798d38885b657c175a4b5c9ea5abd2exeVidar